Live data from Hacker News

LastPass stores passwords so securely, not even its users can access them

theregister.co.uk

21–30 of 266 posts

Re: LastPass stores passwords so securely, not even its users can access them

#21
post #16

Earlier quoted context omitted.

Keepass does support storing the database file locally. It is the default way it works.

A local-only storage solution with your own syncing is by far the best way. Also, storing low security passwords (eg Netflix) in chrome / iOS keychain seems like a pretty safe trade off to me.

I'm still having issues convincing friends/family that the initial friction of a password manager and replacing all of your reused passwords is worth it at all.

Security is a battle of convenience, and we still haven't struck gold for the layman to have decent enough security hygiene.

Re: LastPass stores passwords so securely, not even its users can access them

#22

If you are looking for an alternative I highly recommend Bitwarden (not affiliated with the company). I switched over from Lastpass around a year and a half ago and am very happy with the service. All of the clients and the server are 100% open source plus you can self host if you want to.

Yep, I saw this and immediately felt vindicated for the move to BitWarden.

My only fault with it is that it's missing the "icon" in the inputs to click-and-fill as LastPass has, but I believe that's on the BitWarden backlog.

Still, I'd take having to press Cmd+Shift+Y over not being able to see access keys or er... any of my passwords.

Re: LastPass stores passwords so securely, not even its users can access them

#23

Some alternatives: * https://keepass.info/ * https://bitwarden.com/ * https://1password.com/

I evaluated a bunch of team password managers last year. Lastpass was really buggy and had a confusing UI. Dashlane also had odd limitations. 1password had a good UI but the "master key" system is difficult for users to use. It was also more expensive. I ended up recommending Bitwarden. Surprisingly the open source option had a great UI and great clients, with the bonus of being open source on both ends.

It’s surprising to me that the “master key” system on 1Password proved difficult for your users. For me, this is one of the simplest things about it: you remember one password that unlocks everything else.

Am I talking about the same thing as you when I call this password the “master key”? I feel like I must be as this is flat-out the thing that makes 1Password easy to use.

Re: LastPass stores passwords so securely, not even its users can access them

#24

I continue to use `pass` [0]. Luckily I'm technically minded, so it's not too hard to manage my GPG keys or manage syncing the git repo every now and then. What it lacks in swish UI and automagically-configured browser extensions it gives in configurability, privacy, control over data, and freedom. [0]: https://www.passwordstore.org/

With the dmenu wrapper (passmenu) or something similar for rofi there is almost no need for a browser extension.

Re: LastPass stores passwords so securely, not even its users can access them

#25

I continue to use `pass` [0]. Luckily I'm technically minded, so it's not too hard to manage my GPG keys or manage syncing the git repo every now and then. What it lacks in swish UI and automagically-configured browser extensions it gives in configurability, privacy, control over data, and freedom. [0]: https://www.passwordstore.org/

Yup... also very happy with pass, with the addition of ansible's passwordstore plugin, qtpass, dpass and various other pass-addons. All my passwords are gpg-encrypted and versioned in git.

Re: LastPass stores passwords so securely, not even its users can access them

#27
post #5

Some alternatives: * https://keepass.info/ * https://bitwarden.com/ * https://1password.com/

Yeah they'll never go down. Why don't these systems support local storage as well? Is there greater security risk in syncing to a local device? Edit: I do not mean browser localStorage

I was a paid user of LastPass for about a decade. I don't mind a subscription-based model, especially if there's cloud-syncing involved (I've evaluated the amount of risk I'm comfortable with, and cloud syncing is fine for my use case). Part of the benefit for a paid account is the ability to access your passwords when there's a network outage.

However, in the year before I left LP, they went down three times, at most for about 4 hours. Each time, I could not access my local vault, not through the browser extension, not through the Android app, and certainly not through the website; no matter what I did, it was nothing but errors, and their support was useless. It just would not work. That was enough to spook me and get me off their service.

I was complacent, thinking that no matter what, I could always see my vault, regardless of network status, until it actually hit the fan. I'm currently with 1Password, which is quite slick (their change on 2FA is what actually got me to give them a try), but I've killed network access to my devices and was able to access my vaults.

Just in case, though, I have KeePassXC as well. You never know.

Re: LastPass stores passwords so securely, not even its users can access them

#28
post #23

Earlier quoted context omitted.

I evaluated a bunch of team password managers last year. Lastpass was really buggy and had a confusing UI. Dashlane also had odd limitations. 1password had a good UI but the "master key" system is difficult for users to use. It was also more expensive. I ended up recommending Bitwarden. Surprisingly the open source option had a great UI and great clients, with the bonus of being open source on both ends.

It’s surprising to me that the “master key” system on 1Password proved difficult for your users. For me, this is one of the simplest things about it: you remember one password that unlocks everything else. Am I talking about the same thing as you when I call this password the “master key”? I feel like I must be as this is flat-out the thing that makes 1Password easy to use.

There are four bits of information you need with 1Password teams

1. The team address .1password.com

2. Your login name (email usually)

3. Your 'secret key'

4. Your 'master password'

I suspect GP is talking about item #3 being the point of confusion.

Re: LastPass stores passwords so securely, not even its users can access them

#30
post #6

Yeah I will never trust a third party password system. Writing down on paper works great. For most unimportant accounts use oauth or make up a random password and forget it - if you need it again reset the password.

I'm sorry but that is just ridiculous and time prohibitive.
Post reply on HN